CVE-2024-13449
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Jan 25, 2025
Updated: Feb 4, 2025
CWE ID 862
Summary
CVE-2024-13449 is a vulnerability affecting the Boom Fest plugin for WordPress. This issue stems from a missing capability check on the 'bf_admin_action' function, which exists in all versions up to 2.2.1. Consequently, authenticated attackers with Subscriber-level access or higher can exploit this weakness to make unauthorized modifications to plugin settings, altering the visual aspects of the impacted websites.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share